If Your Password Is 123456, Just Make It HackMe
#1
By ASHLEE VANCE

Back at the dawn of the Web, the most popular account password was “12345.”

Today, it’s one digit longer but hardly safer: “123456.”

Despite all the reports of Internet security breaches over the years, including the recent attacks on Google’s e-mail service, many people have reacted to the break-ins with a shrug.

According to a new analysis, one out of five Web users still decides to leave the digital equivalent of a key under the doormat: they choose a simple, easily guessed password like “abc123,” “iloveyou” or even “password” to protect their data.

“I guess it’s just a genetic flaw in humans,” said Amichai Shulman, the chief technology officer at Imperva, which makes software for blocking hackers. “We’ve been following the same patterns since the 1990s.”

Mr. Shulman and his company examined a list of 32 million passwords that an unknown hacker stole last month from RockYou, a company that makes software for users of social networking sites like Facebook and MySpace. The list was briefly posted on the Web, and hackers and security researchers downloaded it. (RockYou, which had already been widely criticized for lax privacy practices, has advised its customers to change their passwords, as the hacker gained information about their e-mail accounts as well.)

The trove provided an unusually detailed window into computer users’ password habits. Typically, only government agencies like the F.B.I. or the National Security Agency have had access to such a large password list.

“This was the mother lode,” said Matt Weir, a doctoral candidate in the e-crimes and investigation technology lab at Florida State University, where researchers are also examining the data.

Imperva found that nearly 1 percent of the 32 million people it studied had used “123456” as a password. The second-most-popular password was “12345.” Others in the top 20 included “qwerty,” “abc123” and “princess.”

More disturbing, said Mr. Shulman, was that about 20 percent of people on the RockYou list picked from the same, relatively small pool of 5,000 passwords.

That suggests that hackers could easily break into many accounts just by trying the most common passwords. Because of the prevalence of fast computers and speedy networks, hackers can fire off thousands of password guesses per minute.

“We tend to think of password guessing as a very time-consuming attack in which I take each account and try a large number of name-and-password combinations,” Mr. Shulman said. “The reality is that you can be very effective by choosing a small number of common passwords.”

Some Web sites try to thwart the attackers by freezing an account for a certain period of time if too many incorrect passwords are typed. But experts say that the hackers simply learn to trick the system, by making guesses at an acceptable rate, for instance.

To improve security, some Web sites are forcing users to mix letters, numbers and even symbols in their passwords. Others, like Twitter, prevent people from picking common passwords.

Still, researchers say, social networking and entertainment Web sites often try to make life simpler for their users and are reluctant to put too many controls in place.

Even commercial sites like eBay must weigh the consequences of freezing accounts, since a hacker could, say, try to win an auction by freezing the accounts of other bidders.

Overusing simple passwords is not a new phenomenon. A similar survey examined computer passwords used in the mid-1990s and found that the most popular ones at that time were “12345,” “abc123” and “password.”

Why do so many people continue to choose easy-to-guess passwords, despite so many warnings about the risks?

Security experts suggest that we are simply overwhelmed by the sheer number of things we have to remember in this digital age.

“Nowadays, we have to keep probably 10 times as many passwords in our head as we did 10 years ago,” said Jeff Moss, who founded a popular hacking conference and is now on the Homeland Security Advisory Council. “Voice mail passwords, A.T.M. PINs and Internet passwords — it’s so hard to keep track of.”

In the idealized world championed by security specialists, people would have different passwords for every Web site they visit and store them in their head or, if absolutely necessary, on a piece of paper.

But bowing to the reality of our overcrowded brains, the experts suggest that everyone choose at least two different passwords — a complex one for Web sites were security is vital, such as banks and e-mail, and a simpler one for places where the stakes are lower, such as social networking and entertainment sites.

Mr. Moss relies on passwords at least 12 characters long, figuring that those make him a more difficult target than the millions of people who choose five- and six-character passwords.

“It’s like the joke where the hikers run into a bear in the forest, and the hiker that survives is the one who outruns his buddy,” Mr. Moss said. “You just want to run that bit faster.”

   
Reply
#2
I don't see Mach1 on that password list. Shhhhh Tongue
Reply
#3
(01-22-2010, 08:57 AM)vamach1 Wrote: I don't see Mach1 on that password list. Shhhhh Tongue

LOL
Maybe they need to do a survey on Mach1 Sites haha
Reply
#4
I see my name, Michael, is on the list. Funny, I have never used it as part of a password!
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Make your classic a better driver Mach 1 Club 0 6,833 09-29-2011, 07:56 AM
Last Post: Mach 1 Club
  Want To Make Your Car Last? Here’s How. Mach 1 Club 0 6,891 07-19-2010, 06:01 AM
Last Post: Mach 1 Club
  Does the Internet Make You Smarter? Dumber? Mach 1 Club 0 8,004 06-06-2010, 06:16 AM
Last Post: Mach 1 Club
  How to make pickles - made easy, and illustrated! Mach 1 Club 0 7,526 05-05-2010, 09:58 AM
Last Post: Mach 1 Club
  How Our Brains Make Memories Mach 1 Club 0 8,481 04-20-2010, 02:14 PM
Last Post: Mach 1 Club
  Please do not change your password Mach 1 Club 0 7,767 04-14-2010, 08:22 AM
Last Post: Mach 1 Club

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Latest Threads
"Jacobra"
Last Post: JTS71 Mach1
06-30-2023 11:13 PM
» Replies: 86
» Views: 152514
My old Queensland Ambulance
Last Post: JTS71 Mach1
06-30-2023 11:08 PM
» Replies: 5
» Views: 2414
New member from San Jose, CA
Last Post: JTS71 Mach1
05-09-2023 08:39 AM
» Replies: 12
» Views: 4489
Saving Seatbelts
Last Post: Jim
02-19-2023 10:23 PM
» Replies: 2
» Views: 9307
Sourcing new wheels
Last Post: JTS71 Mach1
01-25-2023 02:34 PM
» Replies: 1
» Views: 2178
Shaker Air Filter
Last Post: JTS71 Mach1
01-08-2023 02:24 AM
» Replies: 3
» Views: 1674
1971 Mach 1 parting out interior parts -...
Last Post: ylwhrse
12-22-2022 01:38 PM
» Replies: 0
» Views: 779
Painting
Last Post: Rare Pony
12-14-2022 06:24 PM
» Replies: 2
» Views: 2169
WELCOME ALL NEW MEMBERS INTRODUCE YOURSE...
Last Post: JTS71 Mach1
08-31-2022 01:36 PM
» Replies: 82
» Views: 159040
1970 mach 1 matching numbers
Last Post: Kstweeter
08-31-2022 10:31 AM
» Replies: 1
» Views: 1244
Brake booster/servo hose length
Last Post: JTS71 Mach1
08-23-2022 09:40 AM
» Replies: 7
» Views: 3392
New Member
Last Post: JTS71 Mach1
08-20-2022 11:18 AM
» Replies: 2
» Views: 1743
smooth window operation on 70 Mach
Last Post: CUSTOMMISER
08-15-2022 12:10 PM
» Replies: 2
» Views: 1706
Blinkers on solid
Last Post: busted21
08-09-2022 03:58 AM
» Replies: 14
» Views: 9242
Blinkers on solid when lights on.
Last Post: JTS71 Mach1
08-08-2022 12:06 PM
» Replies: 1
» Views: 1890
351 cj running hot
Last Post: busted21
08-08-2022 12:13 AM
» Replies: 5
» Views: 3726
What's One More Iron In The Fire!
Last Post: Steven Harris
07-22-2022 01:39 PM
» Replies: 124
» Views: 241169
Major Winter projects
Last Post: JTS71 Mach1
07-09-2022 05:12 AM
» Replies: 49
» Views: 22472
Happy Fathers Day!!!
Last Post: JTS71 Mach1
06-20-2022 02:34 AM
» Replies: 0
» Views: 1842
1969 Raven Black 390 Looking For
Last Post: mason1958
06-11-2022 09:48 AM
» Replies: 10
» Views: 15575

>